Compliance. Not theater.
Blue Reacher sits between your CRM and your customer's phone. This page publishes practices, agreements and the vendor list rather than badges.
Ten claims, every one backed by a document you can open right now
- GDPRReady
- CCPA and CPRAReady
- TCPACompliant
- HIPAABAA available
- PCI DSSSAQ-A
- SOC 2Aligned controls
- AES-256At rest
- TLS 1.3In transit
- MFAEnforced
- Data residencyUnited States
Every badge above links to the section that expands it, and every one of those sections links the document behind the claim. Compare that to the badge rows on the rest of this category, which link nowhere.
Every claim carries proof
Each row links the document behind it. Where a third party's signature is missing, this page says so.
- GDPRReady
- Blue Reacher acts as processor and you act as controller. A data processing agreement is published in full, standard contractual clauses cover transfers, and data subject access, correction, erasure, portability and objection requests are handled inside 30 days. Read the detail
- CCPA and CPRAReady
- California residents can request access, correction, deletion and a record of disclosure. Blue Reacher sells no personal information and shares none for cross-context behavioural advertising, so there is no opt-out of sale to build because there is no sale. Read the detail
- TCPACompliant
- Opt-outs are detected automatically, honored immediately, and enforced at the platform rather than inside your sequence logic. Suppression cannot be overridden over the API, every enforcement event is logged, and the consent and list rules we hold customers to are published in full. Read the detail
- HIPAABAA available
- No authority issues a HIPAA certificate. What makes the claim real is a signed business associate agreement, and Blue Reacher signs one on Enterprise plans. The controls that agreement rests on, encryption, access logging, retention limits and verified deletion, are listed below. Read the detail
- PCI DSSSAQ-A
- Card data never touches Blue Reacher systems. Payment pages are hosted entirely by Stripe, a PCI DSS Level 1 service provider, which puts Blue Reacher in the SAQ-A category: the smallest scope the standard defines. Read the detail
- SOC 2Aligned controls
- Blue Reacher's controls are mapped to the SOC 2 Trust Services Criteria for security, availability and confidentiality, and the mapping is handed over on request rather than described. What Blue Reacher will not do is print a seal it has not earned: the independent attestation has not been completed and this page says so, which is more than you get from the two platforms in this category displaying a SOC 2 badge with no report behind it. Read the detail
- AES-256At rest
- Stored data, including contact records and message history, is encrypted at rest with AES-256. Keys are managed through the cloud provider's key management service and are never held in application code. Read the detail
- TLS 1.3In transit
- Traffic between your browser, your CRM and Blue Reacher is encrypted with TLS 1.3, falling back no lower than 1.2. API access is authenticated with per-customer bearer keys you rotate yourself, without asking us. Read the detail
- MFAEnforced
- Multi-factor authentication is required on every account with access to production systems, with no exemptions and no shared logins. Access is least-privilege, reviewed on a schedule, and every touch of production data writes an audit entry. Read the detail
- Data residencyUnited States
- Customer data is stored and processed in United States infrastructure. Production, staging and development are isolated from one another, and internal tooling is never exposed publicly. Read the detail
Disclosure beats badges
Blue Reacher publishes the DPA, names every subprocessor, answers 15 security-review questions, and states gaps plainly. The controls are contractually binding in writing today.
Every document, published, not on request
Data processing agreement
Full DPA covering roles, scope, subprocessors, transfers, breach notification and deletion.
Subprocessor list
Every vendor, what it accesses and where it runs. Published, not on request.
Privacy policy
Collection, retention, and rights under GDPR, CCPA and CPRA.
Anti-spam and acceptable use
Consent rules, opt-out enforcement, list practices and program restrictions.
Deletion and export
Request deletion or export; 30-day completion window.
Security overview
Infrastructure, encryption, access control, monitoring, backups and incident response.
Controls, in the categories reviewers ask about
Security reviews arrive in the same six shapes almost every time, so the answers are grouped the way the questionnaire groups them. A fuller control mapping against the SOC 2 Trust Services Criteria goes out on request.
- Access control
- Role-based least-privilege access, no standing access, MFA required, audit logs retained 90+ days.
- Infrastructure security
- US cloud infrastructure. Production, staging and development isolated. Zero-downtime deployments with automated rollback.
- Data protection
- TLS 1.3 in transit, AES-256 at rest. Workspaces logically isolated. Automated backups with verified integrity.
- Incident response
- Documented response plan. Breach notification within 48 hours, aligned to GDPR Article 33.
- Vendor management
- Every subprocessor reviewed and carries DPA protections. List published at /subprocessors. 30 days notice on changes.
- Application security
- Code review before production. Dependency scanning. Secrets in vaults, never in source control.
Posture reviewed November 10, 2025
Pre-answered security review questions
What can a security reviewer read before signing?
Controls mapped to the SOC 2 Trust Services Criteria for security, availability and confidentiality, the signed DPA, the subprocessor list, and a completed security questionnaire. The full control mapping goes out on request.
Will Blue Reacher sign a DPA?
Yes. Published in full at /dpa. Standard contractual clauses cover transfers out of the US.
Will Blue Reacher sign a BAA for protected health information?
Yes, on Enterprise plans. Controls include encryption in transit/at rest, least-privilege access with audit logging, and verified deletion.
Where is customer data stored?
US cloud infrastructure. Production, staging and development isolated. Workspaces logically isolated by account.
How is data encrypted?
TLS 1.3 in transit (fallback TLS 1.2), AES-256 at rest. Keys managed by cloud provider.
Who inside Blue Reacher can see customer messages?
Least-privilege access, MFA required, no standing access. All access logged, 90+ day retention.
Is customer data used to train AI models?
No. Data never sold, shared between customers or used for public AI training. Anonymized metrics only.
What happens to our data when we leave?
Request deletion or export anytime. Deletion within 30 days. Data retained 90 days post-termination for exports.
Who are the subprocessors?
Full list at /subprocessors with purpose, data category and region. 30 days notice on changes.
How quickly are breaches reported?
Within 48 hours of discovery, aligned to GDPR Article 33. Notification includes nature, data categories and remediation.
Does Blue Reacher handle card data?
No. Stripe hosts payments (PCI DSS Level 1). Blue Reacher is in SAQ-A category.
How are opt-outs enforced?
Automatic detection, immediate enforcement, permanent account-wide. Suppression cannot be overridden via API.
Does Blue Reacher offer single sign-on?
Not today. Per-user credentials with MFA available. API uses rotatable per-customer bearer tokens.
What does support look like?
24/7 and 1:1 on Slack, on every plan, with the team that builds the funnels. No ticket queue, no tiers.
How do we report a vulnerability?
Email support@bluereacher.com or use /.well-known/security.txt. Coordinated disclosure welcome, good-faith researchers credited.
Not answered here?
Send your questionnaire and get back the control mapping, subprocessor list and countersigned DPA the same week. support@bluereacher.com